[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Cryptoswap -- was Re: raw disk access



Hi!

* Hubert Chan <hubert@uhoreg.ca> [20030115 04:20]:
> >>>>> "Rolf" == Rolf Kutz <kutz@netcologne.de> writes:
> Rolf> * Quoting Joshua SS Miller (joshua@fitsnips.net):
> >> Cryptoswap?  Hmm sound like something I was thinking about earlier
> >> today.  Do you have a good resource for this?
> 
> Rolf> http://www.kerneli.org/index.php
> 
> Do the kerneli modules (officially) work with encrypted swap?  I know
> loop-AES does, but I couldn't find anything about the kerneli
> (cryptoapi/cryptoloop) modules.  (For loop-AES, do a Google search for
> it.)
> 
> When encrypting swap, you need to make sure that you don't allocate new
> memory.  Otherwise, it may cause some swapping, which makes you do
> encryption, which may allocate new memory, ad infinitum.  loop-AES takes
> care of that explicitly, by preallocating memory, but I don't think
> cryptoapi/cryptoloop does, so you may be taking your chances with it.

FUD alert! I like loop-AES, too, and would REALLY love general inclusion
into Debian kernels, but this doesn't mean the authors of alternatives
are/may be idiots.

Please don't spread Fear, Uncertainty and Doubt without referring to
facts you're sure of. Leave that to Mickeysoft ;)

My EUR 0.02.

   Count

-- 
Andreas Kotes - ICQ: 3741366 - The views expressed herein are (only) mine.
Unser Leben ist das, wozu unser Denken es macht. -- OpenPGP key 0x8F94C228
Our Life is what our thinking makes it.. Your mind is a weapon! Load it ..

Attachment: pgprtMkGaeHSU.pgp
Description: PGP signature


Reply to: